Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CCMv4 in OSCAL Format #56

Open
aj-stein-nist opened this issue Aug 3, 2022 · 4 comments
Open

CCMv4 in OSCAL Format #56

aj-stein-nist opened this issue Aug 3, 2022 · 4 comments

Comments

@aj-stein-nist
Copy link

Hello, I hope this is a good place to report this. Given the emergence of useful continuous audit metrics like these, and their relationship to CCMv4 controls, is there any work on the roadmap (for this project team or more generally in CSA) to release a draft or finalized copy of the CCMv4 controls in OSCAL data formats (one or all of OSCAL JSON, XML, or YAML)?

The NIST OSCAL Team would be willing to help where we can to assist this effort, where we can, to move forward this effort. Please reach out to via Gitter, email at [email protected], or any other medium we recommend on our website. Thanks!

@pritikin
Copy link
Collaborator

pritikin commented Aug 4, 2022

We fully agree with the goal. Where we needed to ref the CCMv4 controls we added them to our own yaml file - which was a bit of a hack.

Our understanding is the CCMv4 group will publish a full set. @apannetrat might have timeline info.

@aj-stein-nist
Copy link
Author

All good! Again, if you want assistance with the review or any challenges in preparing and releasing the catalog, feel free to let us know. We want to support community adoption when we can reasonably pitch in, @pritikin and @apannetrat.

@mosi-k-platt
Copy link
Collaborator

@pritikin @apannetrat OSCAL rules could be a good use case for continuous audit metrics. @aj-stein-nist can provide more info if you have any questions after reading the doc.

@aj-stein-nist
Copy link
Author

We fully agree with the goal. Where we needed to ref the CCMv4 controls we added them to our own yaml file - which was a bit of a hack.

Our understanding is the CCMv4 group will publish a full set. @apannetrat might have timeline info.

@apannetrat any update on this?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

3 participants